Tag: Oracle Critical Patch Update January 2013

As reported by Ars Technica, the 15th February, Facebook was victim of a watering hole attack, involving a “popular mobile developer Web forum“. The attack was using a Java 0day that has been urgently patched, in Oracle Java CPU of first February, by version 7 update 11 and version 6 update 39.

Four days after the news on Facebook, the 19 February, Reuters also mentioned Apple as a victim of the Oracle Java 0day. The same “popular mobile developer Web forum” was mentioned, but with the precision that this website is a “popular iPhone mobile developer Web forum”. People briefed on the case said that hundreds of companies were affected by this Java 0day, including defense contractors.

Another interesting fact is that Apple had blacklist Java Web plug-in, a second time in a month, the 31 January, through an update to Xprotect, the Mac OS X “anti-malware” system. Surely a reaction the breach reported in the press 19 days later.

Today, Ars Technica released the name of the “popular iPhone mobile developer Web forum”, aka www.iphonedevsdk.com. Now we can gather some information’s related to this watering hole attack.

On urlQuery we can find an interesting submission, the 23 January, who reveal that some Java code was involved during the visit of the web site.

On JSUNPACK we can find another interesting submission, the 22 January, related to the www.iphonedevsdk.com. This submission reveals another website who is min.liveanalytics.org with URL “min.liveanalytics.org/cache.js?1358893681579“. The “cache.js” JavaScript was no more present at this date.

liveanalytics.orgdomain name was created the 8 December October 2012, through Public Domain Registry registrar. All contact information’s are hidden behind PrivacyProtect.org. Privacy Protection ensures that private information of domain owners are not published by replacing all the publicly visible contact details with alternate contact information.

But going back on the first urlQuery submission, we can see that www.iphonedevsdk.com website was doing three requests to min.liveanalytics.org website.

First call was to “/cache.js?1358897354865” JavaScript with a date of “Tue, 22 Jan 2013 23:21:31 GMT“. “1358897354865” return the number of milliseconds since 1970/01/01.

Second call was to “/jquery.js?ummrznjf” JavaScript with the same date.

Third call was to “empty.htm” with additional parameters who are “empty.htm?id=0&ts=X&n=fp&s=Y“. In the following screenshot you will se that X value of ts variable return the number of milliseconds since 1970/01/01. Also in the following screenshot you will see a base64-encoded string:

These kinds of behaviors make me think to a statistic backend like Jsbug, but I don’t have enough information’s to validate my doubts.

By doing some additional researches on urlQuery, regarding min.liveanalytics.org, we can find a submission dating from the 23 January with one screenshot. And by doing also additional researches on urlQuery, regarding www.iphonedevsdk.com, we can observe that min.liveanalytics.org was down the 24 January.

Now let try other occurrences for www.iphonedevsdk.com ormin.liveanalytics.org in search engines & search engines caches. No luck, Google and his cache are not revealing any information’s, same for Bing and other popular search engines. But WayBack Machine is providing a cached version of www.iphonedevsdk.comfor the 15 January, and, and you got it Google Chrome is presenting a nice warning screen regarding min.liveanalytics.org 😉

It is confirming us that this website was hosting some malware and that www.iphonedevsdk.com was including JavaScript calls to min.liveanalytics.org the 15 January, date of the Wayback Machine capture. If you take a look at the source code of cached version of www.iphonedevsdk.comyou can see this, a nice JavaScript inclusion.

So we have a timeline associated with this domain:

Domain name was registered the 8 December October with hidden information’s

WayBack Machine report us that the website was infected the 15 January

urlQuery & JSUNPACK report us that the website was up the 22/23 January

urlQuery report us that the website was down the 24 January

Another interesting timeline is the Oracle Java patch and life cycle:

11 December 2012: Oracle release, through a CPU, Java SE 7 Update 10 who introduced the levels of security for applet execution.

13 January 2013: Oracle release an alert and update, Java SE 7 Update 11, for a Java 0day able to bypass the security manager.

1 February 2013: Oracle release, through an out-of-band CPU, Java SE 7 Update 13, in order to fix a 0day exploited in the wild.

As you can see, Java SE 7 Update 10, released the 11 December, has introduce the levels of security (“Medium” by default) and bunch of pop-ups, who are warning you about the trust of an applet. Java SE 7 Update 11, released the 13 January, has force the level of security from “Medium” to “High“. With the “High” setting, the user is always prompted before any unsigned Java applet or Java Web Start application is run.

What I can suppose regarding these timelines:

First, the victims of this watering hole campaign didn’t have potentially updated to the latest version.

Second, the victims of this watering hole campaign did have potentially update to JSE 7U11, but have not change the default security level from “Medium” to “High“, despite all the history in Java 0days and advises of security experts.

Third, the victims, have potentially detect the attack when JSE 7U13 was out, because the “High” security level shown them some unusual applet execution on the “popular iPhone mobile developer Web forum”.

Was this campaign a highly targeted attack? I don’t think so, why because Oracle Java has a long history of 0days, and serious companies like Twitter, Facebook and Apple should have disable Java Web Start application for non trusted applets since a while.

Updates

F-Secure has provide in a blog post 2 other domain names involved in the Facebook, Apple and Twitter compromise, this domain name are:

cloudbox-storage.com

digitalinsight-ltd.com

By investigating on these domain names, I found some worrying information’s. If these information’s are confirmed then the story is complete different and could have a bigger impact.

“digitalinsight-ltd.com” domain name was registered the 2012-03-22. By doing some Google dorks we can find these informations:

A post on Fedoraforum.org, dating from 2012-07-14 mentioning this domain name… and a user of the forum wonder why a JavaScript inclusion is done to this domain.

Microsoft has release, the 12 February 2013, during his February Patch Tuesday, one updated security advisory and twelve security bulletins. On the twelve security bulletins five of them have a Critical security rating.

Microsoft Security Advisory 2755801

MSA-2755801,released during September 2012, has been updated. The security advisory is regarding updates for vulnerabilities in Adobe Flash Player in Internet Explorer 10. Update KB2805940 has been released for supported editions of Windows 8, Windows Server 2012, and Windows RT. The update addresses the vulnerabilities described in Adobe Security bulletin APSB13-05.

MS13-020security update, classified as Critical, allowing remote code execution, is the fix for one publicly reported vulnerability. CVE-2013-1313 (9.3 CVSS base score) was discovered and reported by an anonymous researcher, working with HP’sZero Day Initiative.

MS13-014security update, classified as Important, allowing denial of service, is the fix for one privately reported vulnerability. CVE-2013-1281 (7.1 CVSS base score) was discovered and privately reported by an anonymous researcher.

MS13-015security update, classified as Important, allowing elevation of privileges, is the fix for one privately reported vulnerability. CVE-2013-0073 (10.0 CVSS base score) was discovered and privately reported by James Forshaw of Context Information Security.

Oracle has provide his Critical Patch Update (CPU) for January 2013 how has been released on Tuesday, January 15. This CPU contains 86 security vulnerability fixes across 24 of Oracle products. On the 86 security vulnerabilities 45 of them may be remotely exploitable without authentication. The highest CVSS Base Score for vulnerabilities in this CPU is 10.0 and concern Oracle Database Mobile. 9 vulnerabilities have a CVSS base score upper or equal to 7.0.

As you may know Oracle is using CVSS 2.0 (Common Vulnerability Scoring System) in order to score the reported vulnerabilities. But as you also may know security researchers disagree with the usage of CVSS by Oracle. Oracle play with CVSS score by creating a “Partial+” impact rating how don’t exist in CVSS 2.0, and by interpreting the “Complete” rating in a different way than defined in CVSS 2.0.

Oracle Database Server

One vulnerability is reported for “Oracle Database Server”. CVE-2012-3220 vulnerability has a CVSS score of 9.0. Affected component is “Spatial” and exploitation require authentication. CVSS score is 9.0 for Windows platform and 6.5 for Linux and Unix.

Oracle Database Mobile/Lite Server

5 vulnerabilities are reported for “Oracle Database Mobile/Lite Server“, all of them are remotely exploitable without authentication. The highest CVSS score is 10.0. Affected component is “Mobile Server“.

13 vulnerabilities are reported for “Oracle Enterprise Manager Grid Control” and all of them may be remotely exploitable without authentication. The highest CVSS score of these vulnerabilities is 7.5. Affected components are “APM – Application Performance Management” and “Enterprise Manager Base Platform“.

One vulnerability is reported for “Oracle Supply Chain Products” and CVE-2013-0370 has a CVSS base score of 2.1. Affected component is “Oracle Agile PLM Framework“.

Oracle PeopleSoft Products

12 vulnerabilities are reported for “Oracle PeopleSoft Products” and 7 of them may be remotely exploitable without authentication. The highest CVSS base score of these vulnerabilities is 5.5. Affected component are “PeopleSoft PeopleTools” and “PeopleSoft HRMS“.

One vulnerability is reported for “Oracle JD Edwards Products” and CVE-2012-1678 has a CVSS base score of 3.5. Affected component is “JD Edwards EnterpriseOne Tools“.

Oracle Siebel CRM

10 vulnerabilities are reported for “Oracle Siebel CRM” and 5 of them may be remotely exploitable without authentication. The highest CVSS score of these vulnerabilities is 5.0. Affected component is “Siebel CRM“.

8 vulnerabilities are reported for “Oracle Sun Products Suite” and 1 of them may be remotely exploitable without authentication. The highest CVSS score of these vulnerabilities is 6.6. Affected components are “Solaris” and “Sun Storage Common Array Manager (CAM)“.

One vulnerability is reported for “Oracle Virtualization” and CVE-2013-0420 has a CVSS base score of these vulnerabilities is 2.4. Affected component is “VirtualBox“.

Oracle MySQL

18 vulnerabilities are reported for “Oracle MySQL” and 2 of them may be remotely exploitable without authentication. The highest CVSS score of these vulnerabilities is 9.0. Affected components are “MySQL Server“.